Privacy
Superfandom stores the information needed to run your account and personalized feed. This includes your email address and optional display name, password hash, linked OAuth provider identifiers and tokens, profile follows, contribution history, private RSS key, and API-key hashes and prefixes. Plaintext passwords and API keys are not stored.
How information is used
Account information authenticates you and supports password recovery. Follows build your private HTML and Atom feeds. Contribution and moderation records protect community content. OAuth data is used only for the provider login or account-linking flow you select.
Logs and cookies
Signed session and CSRF cookies keep you signed in and protect forms. Operational logs record request IDs, methods, URL paths, response status, and duration. Application request logs deliberately exclude query strings, including private RSS keys. The outer web server and configured identity or mail providers may maintain their own operational records.
Sharing and external services
Superfandom does not sell account information. Data is sent to Google or Facebook only when you choose the corresponding OAuth flow, and to the configured mail provider for account email. Public profiles, news, aliases, editor names, and change history may be visible as part of the community service. Following a source link takes you to an independent website with its own privacy practices.
Retention and security
Account and community records are retained while needed to operate, moderate, recover, and back up the service. Revoking an API key or rotating an RSS key immediately invalidates the old credential. Backups are retained for recovery and may contain earlier account data until they expire.
Questions
For privacy questions or an account-data request, contact admin@superfan.moe. Identity verification may be required before account information is changed or disclosed.